HG10
Tenda- Product type
- Operating system
- Catalog vulnerabilities
- 14
Severity across 14 analyzed records
Verify to analyze this security profile
en
Severity across 14 analyzed records
Verify to analyze this security profile
As of 10/06/2026, within CyStack's analyzed data, HG10 has 7 security vulnerabilities published in the last 90 days. Of these, 7 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of HG10 and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-104610Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published10/02/2026 | SeverityCritical |
CVE-2026-86167Tenda HG10 Boa formgponConf os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published09/06/2026 | SeverityCritical |
CVE-2026-86166Tenda HG10 Boa Web Server formWanRedirect buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published09/06/2026 | SeverityHigh |
CVE-2026-86165Tenda HG10 formURL buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published09/06/2026 | SeverityCritical |
CVE-2026-85110Tenda HG10 Boa Web Server formWlanSetup buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published09/03/2026 | SeverityHigh |
CVE-2026-85109Tenda HG10 Boa Web Server formLogin buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published09/03/2026 | SeverityCritical |
CVE-2026-82542Tenda HG10 Boa Web Server formIPv6Routing buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published08/30/2026 | SeverityCritical |
CVE-2026-11553Tenda HG7/HG9/HG10 formPPPEdit stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/08/2026 | SeverityHigh |
CVE-2026-11499Tenda HG7/HG9/HG10 formDOMAINBLK stack-based overflow | Exploitation statusNot known exploited | FixNot confirmed | Published06/08/2026 | SeverityCritical |
CVE-2026-11498Tenda HG7/HG9/HG10 Web Management voip_other_set asp_voip_OtherSet stack-based overflow | Exploitation statusNot known exploited | FixNot confirmed | Published06/08/2026 | SeverityHigh |
CVE-2026-6988Tenda HG10 Boa Service formRouting formRoute buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/25/2026 | SeverityHigh |
CVE-2026-1690Tenda HG10 formSysCmd system command injection | Exploitation statusPublic exploit | FixNot confirmed | Published01/30/2026 | SeverityMedium |
CVE-2026-1689Tenda HG10 Login formLogin checkUserFromLanOrWan command injection | Exploitation statusPublic exploit | FixNot confirmed | Published01/30/2026 | SeverityMedium |
CVE-2026-1687Tenda HG10 Boa Webserver formSamba command injection | Exploitation statusPublic exploit | FixNot confirmed | Published01/30/2026 | SeverityMedium |